SOC 2 Type II
In progressControls are implemented and evidence collection is running. The observation window is underway; the report will be available under NDA once the audit completes.
Trust Center
You are trusting us with officer locations, incident reports and client records. Here is exactly how we protect them. Last reviewed September 9, 2026.
Compliance
Controls are implemented and evidence collection is running. The observation window is underway; the report will be available under NDA once the audit completes.
An Information Security Management System is documented and operating against the 93 Annex A controls. Stage 1 and Stage 2 certification audits with an accredited body are the remaining steps.
Data processing addendum, Standard Contractual Clauses, published sub-processor list, documented retention schedule and a 30-day data subject request process.
Notice at collection, request handling and non-discrimination. We do not sell or share personal data.
An independent external test is scheduled ahead of general availability; the summary letter will be shareable under NDA.
Controls
These are the controls in place today, not aspirations. Each one is evidenced in our SOC 2 readiness programme and mapped to ISO/IEC 27001:2022 Annex A.
TLS 1.2 or better for everything in transit. AES-256 for data at rest, including database volumes, file storage and backups.
Least-privilege, role-based access to production. Single sign-on with mandatory multi-factor authentication for staff. Access is reviewed quarterly and revoked the day someone leaves.
Row-level security enforced at the database, so a query can only ever return the rows belonging to the authenticated account.
Append-only logs of authentication, plan changes, data exports and deletion requests. Logs cannot be edited or deleted by any application role and are retained for two years.
Automated encrypted daily backups with point-in-time recovery. Restores are tested on a regular schedule. Recovery targets: RPO 24 hours, RTO 8 hours.
Continuous uptime and error monitoring with on-call alerting, plus dependency vulnerability scanning on every build.
Peer-reviewed changes, automated type and lint checks, separate development and production environments, and secrets held in a managed secret store — never in source code.
A documented response plan with defined severities and owners. Confirmed personal data breaches are reported to affected customers within 48 hours of confirmation.
Every sub-processor is reviewed for security and privacy posture before onboarding and re-reviewed annually. The current list is published.
Reporting
If you believe you have found a vulnerability, email security@guardresourceone.com with enough detail to reproduce it. We acknowledge reports within two business days and aim to confirm a fix timeline within ten.
Please do not run automated scans against production, access data that is not yours, or disclose the issue publicly before we have had a chance to fix it. We will not pursue legal action against researchers who follow these guidelines.
Requesting documents? Our Data Processing Addendum, sub-processor list and Privacy Policy are public, as is our ISO/IEC 27001 control mapping. The SOC 2 report and penetration test summary are shared under NDA once available.